PR_SET_NO_NEW_PRIVS
(2const)set the calling thread's no_new_privs attribute
#include <linux/prctl.h> /* Definition of PR_* constants */ #include <sys/prctl.h> int prctl(PR_SET_NO_NEW_PRIVS, 1L, 0L, 0L, 0L);
LIBRARY
DESCRIPTION
Set the calling thread's no_new_privs attribute. With no_new_privs set to 1, execve(2) promises not to grant privileges to do anything that could not have been done without the execve(2) call (for example, rendering the set-user-ID and set-group-ID mode bits, and file capabilities non-functional).
Once set, the no_new_privs attribute cannot be unset. The setting of this attribute is inherited by children created by fork(2) and clone(2), and preserved across execve(2).
RETURN VALUE
ERRORS
- EINVAL
- The second argument is not equal to 1L.